VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,267)

page 151 of 164
  • CVE-2026-15992HigJul 28, 2026
    risk 0.00cvss 8.8epss 0.00

    The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing authorization checks and nonce verification in the `get_user()` function of the `Module_Password_Hint` class, which unconditionally…

  • CVE-2026-14328HigJul 28, 2026
    risk 0.00cvss 8.8epss 0.00

    The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.1. This is due to insufficient authorization on the `wp_ajax_pos_get_option` AJAX handler, which…

  • CVE-2026-14545CriJul 28, 2026
    risk 0.00cvss 9.8epss 0.00

    The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take…

  • CVE-2026-66015HigJul 27, 2026
    risk 0.00cvss 7.2epss 0.00

    An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned account conditions. Successful exploitation may grant temporary platform administrator access.

  • CVE-2026-66399MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows administrators with only group-management permissions to join privileged groups without verification of required rights. Attackers can add themselves to…

  • CVE-2026-13152HigJul 27, 2026
    risk 0.00cvss 8.1epss 0.00

    The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user who registers an…

  • CVE-2026-12394CriJul 27, 2026
    risk 0.00cvss 9.8epss 0.00

    The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise.

  • CVE-2026-12502HigJul 24, 2026
    risk 0.00cvss epss 0.00

    Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker to reset the password of any LARM user (including the `larmapp` service…

  • CVE-2026-10610HigJul 24, 2026
    risk 0.00cvss epss 0.00

    Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user.

  • CVE-2026-7483HigJul 24, 2026
    risk 0.00cvss epss 0.00

    Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a privileged user.

  • CVE-2026-12981HigJul 24, 2026
    risk 0.00cvss 7.5epss 0.00

    The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.

  • CVE-2026-12497HigJul 24, 2026
    risk 0.00cvss 7.5epss 0.00

    The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection field. The set of roles offered…

  • CVE-2026-12736HigJul 24, 2026
    risk 0.00cvss 8.0epss 0.00

    The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This is due to the SettingsApi::save_option() REST route (POST /wp-json/wpify-woo/v1/option) passing the request-supplied 'option' and 'data' parameters directly to…

  • CVE-2026-16764MedJul 23, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such manipulation of the argument is_staff leads to improper privilege management. The attack may be…

  • CVE-2026-38764HigJul 23, 2026
    risk 0.00cvss 7.8epss 0.00

    An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys

  • CVE-2026-15630CriJul 23, 2026
    risk 0.00cvss 9.9epss 0.00

    A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).

  • CVE-2026-65897HigJul 23, 2026
    risk 0.00cvss 8.8epss 0.00

    Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write callers to assign invited accounts to groups that grant api.super permissions. Attackers can create invitation records with…

  • CVE-2026-15017HigJul 23, 2026
    risk 0.00cvss 8.8epss 0.00

    The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and nonce verification in the `MDJM_Permissions::set_permissions()` and `MDJM_Employee_Manager::init()`…

  • CVE-2026-61246HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network…

  • CVE-2026-60455HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network…